fix(runtime): reconcile lifecycle CI contracts

- Regenerate website/configuration-reference.md: Wave 5B moved the
  ODYSSEUS_BROWSER_SCREENSHOT_DIR read in web_tools.py (3458 -> 3479).
- Give the Chrome sweep regression fixture a real process identity (stat
  start time, boot id, process_ownership.PROC_ROOT). The sweep now signals
  only verified identities; the old cmdline-only fixture borrowed the
  identity of whatever real process held pid 101 on the host, so it passed
  or failed depending on the machine.
- Import pytest in test_workspace_artifact_tool_floor.py: its existing
  bubblewrap capability skip raised NameError on hosts without functional
  namespaces.

No production code changes. Required containment still fails closed.
This commit is contained in:
Alexandre Teixeira
2026-10-02 02:23:07 +01:00
parent b4b5412cda
commit 1bf45b9fed
3 changed files with 23 additions and 2 deletions
+1 -1
View File
@@ -90,7 +90,7 @@ The source tree reads **109** `ODYSSEUS_*` variables: 79 an operator may want to
| `ODYSSEUS_BROWSER_MCP_REQUIRE_CACHE` | `''` | `src/builtin_mcp.py:90` | Truthy refuses to start the browser MCP server unless its npm package is already in the npx cache, instead of installing it at startup. |
| `ODYSSEUS_BROWSER_NAMESPACE` | `'odysseus-ui'` | `src/agent_tools/web_tools.py:100` (+3 more) | Namespace for the detached agent-browser daemon's pid files, so two runtimes on one machine do not terminate each other's browsers. |
| `ODYSSEUS_BROWSER_NO_SANDBOX` | `'1'` | `src/builtin_mcp.py:142` | Security-relevant. On by default, adding `--no-sandbox` because the Docker image cannot use the Chromium sandbox. Set 0, false or no to keep it. |
| `ODYSSEUS_BROWSER_SCREENSHOT_DIR` | *unset* | `src/agent_tools/web_tools.py:3458` | Where private-browser screenshots are written. Falls back to the container path, then the system temp directory. |
| `ODYSSEUS_BROWSER_SCREENSHOT_DIR` | *unset* | `src/agent_tools/web_tools.py:3479` | Where private-browser screenshots are written. Falls back to the container path, then the system temp directory. |
### Container and workspace mounts